Engagement lifecycle

The Silver Team methodology

A structured lifecycle for turning adversary simulation into both a security assessment and a workforce resilience exercise.

1

Authorize

Define mission, scope, safety, and learning goals.

Agree on authorized targets, prohibited actions, emergency contacts, evidence handling, safety boundaries, and what behaviors the organization wants to observe or strengthen.

2

Understand

Study the organization as both attacker and educator.

Identify realistic attack paths, employee workflows, decision points, reporting channels, and places where defenders should reasonably be able to notice something unusual.

3

Design

Build adversary objectives and defender opportunities together.

Define realistic attack objectives while deliberately placing catch points where employees can verify identity, challenge access, question a request, or report suspicious behavior.

4

Simulate

Apply credible pressure without turning realism into recklessness.

Execute within scope and document both attacker progress and human defensive signals. The purpose is observation and improvement, not collecting trophies.

5

Create the win

Make sure a meaningful defender success can happen.

Allow the planned opportunity to work. When an employee recognizes, challenges, reports, verifies, or interrupts the activity, treat that as valuable evidence of resilience.

6

Reinforce

Turn the moment into learning.

When the rules of engagement permit, positively reinforce the employee’s behavior and explain what signal they recognized or what action made the difference.

7

Measure

Capture failure paths and success signals.

Record compromise, detection, challenge, escalation, reporting, recovery, response time, and process friction. A useful report explains why behaviors happened.

8

Improve

Strengthen people, process, technology, and culture.

Translate observations into changes that make the correct action easier next time. Preserve what worked, fix what did not, and repeat the exercise to measure progress.

Evidence model

Report both sides of the encounter.

Adversary evidence

  • Objective reached or blocked
  • Attack path and decision points
  • Controls bypassed or effective
  • Time, friction, and escalation
  • Potential business impact

Defender evidence

  • Suspicion or anomaly recognized
  • Identity or request verified
  • Challenge performed
  • Report or escalation made
  • Recovery after initial compliance
  • Positive behavior worth scaling